Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns

Reported 20 Aug 2026 by otx · Severity: medium

On August 20, 2026, malicious versions of three Rust crates were published to crates.io: arrayref@0.3.10, internment@0.8.7, and append-only-vec@0.1.9. The malicious crates added a typosquatted dependency (proc-macro1) whose build script downloads and executes a remote binary at c